Malware xHelper is embedded in an app that masquerades as a popular speed-up utility for smartphones. The malware uses a Russian nesting-doll type architecture to worm its way into the heart of Android devices. The infection chain starts by convincing a victim to download a rogue trojanized app. Another dropper, called Leech, nested inside the Helper downloader, then swings into action by installing the Triada trojan, whose chief feature is a set of exploits for obtaining root privileges.
Source: https://threatpost.com/xhelper-russian-nesting-doll-android-malware/154519/

